← All courses
Track Β· Cloud Β· Beginner β†’ Intermediate

The cloud that enterprises and governments run on.

From what the cloud is to launching virtual machines, web apps and databases on Azure. Aligned to the AZ-900 Fundamentals and AZ-104 Administrator paths β€” the certifications employers ask for by name.

Start learning See the labs
Level
Beginner β†’ Intermediate
Lessons
24 notes
Labs
8 hands-on
Maps to
AZ-900 Β· AZ-104
Price
Free to read
Your progress0%
The curriculum

Read, do, complete, move on.

Open a lesson, read the notes, then mark it complete. Your progress is saved on this device.

Level 1 Β· Beginner

AZ-900 Fundamentals: the concepts and the core services

This level gives you the language of the cloud and a map of Azure’s main services, security and pricing β€” exactly what the AZ-900 Fundamentals certification tests. No code required.

01

Cloud concepts

Foundations
β€ΊWhat the cloud is, and the three service modelsβœ“

The cloud is renting computing β€” servers, storage, software β€” over the internet instead of owning it. Microsoft runs data centres worldwide; you use what you need and pay for that.

More controlLess to manageIaaSYou manageVMs, OS, runtime, appProvider managesPaaSYou manageJust your appProvider managesSaaSYou manageNothing β€” just use itProvider manages
IaaS β†’ PaaS β†’ SaaS: how much you manage

Three models describe how much Microsoft manages versus you:

  • IaaS (Infrastructure) β€” you rent raw virtual machines and manage the rest. Most control.
  • PaaS (Platform) β€” you give Microsoft your app; it runs the servers for you.
  • SaaS (Software) β€” you just use finished software, like Microsoft 365. Least worry.
Example: Renting a VM to install your own software is IaaS. Deploying a website to Azure App Service without touching a server is PaaS. Using Outlook in the browser is SaaS β€” you manage nothing.
β€ΊCapEx vs OpEx, and why it mattersβœ“

Buying your own servers is capital expenditure (CapEx) β€” a big payment upfront for hardware you then own and maintain. The cloud turns this into operational expenditure (OpEx) β€” a running cost you pay as you go, like electricity.

This is the business heart of the AZ-900 exam, and it is not just accounting. OpEx means you can start tiny, with no capital, and only pay more as you grow and earn.

For us: For a Cameroonian startup or student, CapEx was always the wall β€” you could not begin without money for hardware. OpEx removes the wall: start with a few dollars a month, grow when the revenue is there. The cloud is, in a real sense, the great unlocker for under-capitalised markets.
β€ΊRegions, availability and the shared responsibility modelβœ“

Azure is organised into regions (geographic areas of data centres). Within many regions there are Availability Zones β€” physically separate data centres β€” so you can run across zones and survive one failing.

YOU secure IN the cloudYour dataAccounts & accessConfigurationAWS/cloud secures OFHardwareGlobal networkData centres
The shared responsibility model

The shared responsibility model is the rule you must never forget: Microsoft secures the cloud itself (buildings, hardware, network); you are responsible for your data, your accounts, and your access settings. The split shifts with the service model β€” more is yours with IaaS, less with SaaS β€” but your data and identities are always yours to protect.

Example: For Central Africa, the North Europe (Ireland) and West Europe (Netherlands) regions usually give good latency. Azure also has a South Africa region (Johannesburg) β€” test both and measure for your users.
02

Core Azure services

The toolbox
β€ΊCompute: VMs, App Service and Functionsβœ“

Azure gives you several ways to run code, from most control to least management:

More controlLess managementVM / EC2you manage the serverContainerspackaged appServerlessjust your function
The compute ladder
  • Virtual Machines β€” full computers you control (IaaS).
  • App Service β€” host a website or API; Azure manages the servers (PaaS).
  • Azure Functions β€” run a small piece of code on an event, no server at all (serverless).
  • Azure Kubernetes Service (AKS) β€” managed Kubernetes for containers.

The skill is choosing the simplest option that fits. A standard website belongs on App Service, not on a VM you have to patch yourself.

β€ΊStorage and networking basicsβœ“

Azure Storage holds your data. The workhorse is Blob Storage for files β€” images, videos, backups β€” with hot, cool and archive tiers that trade cost against access frequency, just like other clouds.

Match storage class to how often you read itHot / Standardused oftenCool / Nearlinenow & thenCold / Archiverarely, cheapLifecycle rule moves data automatically β†’ saves money
Storage tiers & lifecycle

Networking starts with the Virtual Network (VNet) β€” your private network in Azure. Resources inside it talk to each other privately, and you open access to the outside world deliberately with Network Security Groups (NSGs), which act as firewalls.

Example: A backup archive that must be kept for legal reasons but is almost never read goes in the Archive tier β€” cents per gigabyte per month β€” instead of paying hot-tier prices to let it sit untouched.
β€ΊIdentity with Microsoft Entra IDβœ“

Microsoft Entra ID (formerly Azure Active Directory) is Azure’s identity service β€” it manages who your users are and what they can sign in to. It is the front door to everything.

Two ideas carry it: authentication (proving who you are) and authorisation (what you are allowed to do). The single most important security feature it offers is Multi-Factor Authentication (MFA) β€” requiring a second proof, like a code on your phone, beyond the password.

For us: Turn on MFA for every administrator account, always. Stolen passwords are the number-one way accounts are breached everywhere; MFA stops almost all of it. For a small team where one admin account controls everything, this one setting is your strongest protection, and it is free.
03

Security, identity and governance

Trust
β€ΊDefence in depth and Azure security toolsβœ“

Good security is not one wall but many layers β€” defence in depth β€” so that if one fails, others still protect you. Azure provides tools at each layer: NSGs and Firewall at the network, Entra ID at identity, encryption for data, and Microsoft Defender for Cloud watching the whole thing and scoring your security posture.

For the exam and for real life, know that data is encrypted at rest (while stored) and in transit (while moving) by default on Azure β€” a strong baseline you get for free.

β€ΊRole-Based Access Control (RBAC)βœ“

RBAC is how you control who can do what in Azure, built on least privilege: grant each person only the access their job needs. You assign a role (a set of permissions) to a user or group, scoped to a specific resource, resource group or subscription.

Too much accessLeast privilegeAppALL resources(risky)App1 bucketread only
Least privilege: grant only what is needed
Example: A junior developer needs to restart one web app but should never be able to delete databases. You give them the Contributor role scoped only to that app’s resource group β€” full control there, zero power everywhere else. Scope is the whole game.
β€ΊGovernance: subscriptions, groups and tagsβœ“

Azure’s structure keeps large estates tidy: a subscription is a billing and management boundary; resource groups bundle related resources so you can manage and delete them together; tags are labels (like env=prod or project=academy) that help you track cost and ownership.

Azure Policy lets you enforce rules automatically β€” for example "no one may create resources outside Europe" β€” so mistakes are prevented, not just caught later.

For us: Even a two-person team benefits from putting each project in its own resource group and tagging by project. When the bill arrives, you know exactly what cost what β€” and you can delete an entire experiment in one click when it is done.
04

Pricing and managing cost

Spend wisely
β€ΊHow Azure pricing worksβœ“

Most Azure services are pay-as-you-go: you pay for what you consume β€” compute per second, storage per gigabyte, data transfer per gigabyte. Prices vary by region and by service tier.

Two tools help you plan: the Pricing Calculator (estimate a design’s cost before you build) and the Total Cost of Ownership (TCO) Calculator (compare cloud against running your own servers). Use the Pricing Calculator before every real project β€” guessing at cloud cost is how bills surprise people.

β€ΊSaving money: reservations and right-sizingβœ“

Pay-as-you-go is flexible but not always cheapest. If you know you will run a server for a year or more, a Reserved Instance commits you to it in exchange for a large discount. Right-sizing means picking a VM that matches real need, not the biggest one "to be safe".

For us: The cheapest resource is the one you turn off. Dev and test servers do not need to run overnight or on weekends β€” shutting them down on a schedule can halve their cost. On a tight budget, these small habits add up to real money kept in the business.
β€ΊCost Management and budgetsβœ“

Microsoft Cost Management shows where your money actually goes β€” by service, by resource group, by tag β€” and lets you set budgets with alerts. Set a budget on day one and let Azure email you well before you reach your limit.

Example: You set a $20 monthly budget with alerts at 50%, 80% and 100%. A forgotten VM starts eating into it; you get the 50% email, spot the VM, and shut it down long before it becomes a painful bill. That early warning is the difference between a small lesson and an expensive one.
Level 2 Β· Intermediate

AZ-104 Administrator: deploy and manage real resources

Now you administer Azure for real β€” identity, compute, storage, networking and deployment β€” using the portal, the Azure CLI and Bicep. These are the day-to-day skills of an Azure Administrator (AZ-104).

05

Identity and the tools

Access and control
β€ΊManaging users, groups and the Azure CLIβœ“

An administrator lives in identity. In Entra ID you create users, bundle them into groups, and assign access to the group β€” so a new hire gets the right access just by joining the group, and loses it by leaving. This scales far better than per-person grants.

You will do much of this with the Azure CLI (az) β€” scriptable and repeatable β€” and Cloud Shell, a browser terminal with az ready to go.

Example: Sign in and list your resource groups: az login then az group list --output table. Because it is commands, you can script onboarding β€” "create this user, add to these groups" β€” and run it identically every time.
β€ΊRBAC assignments in practiceβœ“

Beyond understanding RBAC, the administrator assigns it correctly. The practical rules: assign roles to groups, not individuals; scope to the narrowest level that works (resource group over subscription); and audit assignments regularly to remove access people no longer need.

Example: Grant a whole team read access to one resource group: az role assignment create --assignee dev-team --role Reader --resource-group academy-rg. One command covers the team now and everyone who joins the group later.
β€ΊConditional Access and MFA at scaleβœ“

Conditional Access (an Entra ID feature) lets you set smart sign-in rules: "require MFA when signing in from outside the office", or "block sign-ins from countries we never operate in". It applies security based on context, not a blanket rule that frustrates everyone.

For us: For a distributed African team working from phones and shared networks, Conditional Access is powerful: enforce MFA for risky sign-ins without making the daily login painful. Security that people will actually tolerate is security that actually works.
06

Compute administration

Run the workloads
β€ΊDeploying and sizing virtual machinesβœ“

The administrator creates VMs with the right size, image and disk, in the right region, and knows how to resize them as needs change. You choose a VM series for the workload (general-purpose, compute-optimised, memory-optimised) and attach managed disks for storage.

Example: Create a Linux VM from the CLI: az vm create --resource-group academy-rg --name web-1 --image Ubuntu2204 --size Standard_B1s. The B-series is burstable and cheap β€” ideal for dev and low-traffic workloads where you do not need constant full power.
β€ΊScaling: availability sets and scale setsβœ“

One VM is a single point of failure. For reliability you spread across an Availability Set or Availability Zones so one hardware fault does not take you down. For handling variable load you use a Virtual Machine Scale Set β€” a group of identical VMs that grows and shrinks automatically with demand.

Pair a scale set with a load balancer and you have a system that absorbs a traffic spike and then shrinks back down to save money when it is quiet.

β€ΊApp Service and containersβœ“

Not everything should be a VM. App Service hosts web apps and APIs as a managed platform β€” you deploy code or a container and Azure handles the servers, patching, scaling and HTTPS certificate. For container-heavy systems, Azure Container Apps or AKS run your containers managed.

Example: Deploy a web app straight from a container image to App Service and get an HTTPS URL in minutes β€” no VM to patch, no certificate to configure. For most websites this is the right answer, and it frees a small team to work on the product instead of the plumbing.
07

Storage and databases

Persist data
β€ΊStorage accounts, blobs and accessβœ“

Data lives in a storage account, which holds blobs (files), file shares, queues and tables. The administrator sets the access tier (hot/cool/archive), configures redundancy (how many copies, and whether across regions), and controls access with SAS tokens β€” time-limited keys that grant exactly the access needed and then expire.

Example: Instead of making a file public forever, you issue a SAS token that allows read access to one file for 24 hours. After that it stops working automatically β€” the right way to share a download without leaving a door open.
β€ΊAzure SQL and Cosmos DBβœ“

Two managed databases cover most needs. Azure SQL Database is managed SQL Server β€” relational, familiar, with backups and high availability handled for you. Azure Cosmos DB is a globally-distributed NoSQL database for apps that need low latency for users anywhere and flexible data.

Choose relational (Azure SQL) for structured, related data (finance, inventory); choose Cosmos DB when you need global reach and flexible documents (a product catalogue serving several countries). Either way, "managed" means you run a serious database without being a full-time DBA.

β€ΊBackup and recoveryβœ“

An administrator who cannot restore data is not doing the job. Azure Backup protects VMs, databases and files on a schedule, and Azure Site Recovery can fail an entire system over to another region in a disaster.

For us: Backups are invisible until the day they save the business β€” and that day always comes eventually. Set up automatic backups from the start, and test a restore at least once. A backup you have never restored is only a hope, not a plan. This discipline separates a professional from an amateur everywhere in the world.
08

Networking, monitoring and automation

Connect and operate
β€ΊVNets, peering and DNSβœ“

The administrator designs the network: VNets divided into subnets, connected to each other with peering, protected by NSGs, and named with Azure DNS. A clean network design β€” separate subnets for web, app and database tiers β€” is both more secure and easier to reason about.

For connecting Azure to an office or another cloud, a VPN Gateway creates a secure tunnel over the internet.

β€ΊAzure Monitor and alertsβœ“

Azure Monitor gathers metrics and logs from everything you run; Log Analytics lets you query them; alerts notify you when something crosses a threshold. The administrator builds dashboards for the signals that matter and wires alerts to email or SMS β€” the same golden-signals discipline, native to Azure.

Example: An alert rule fires when a VM’s CPU stays above 90% for 10 minutes, emailing the team. You learn about a struggling server from Azure, not from a customer β€” and you act before it falls over.
β€ΊInfrastructure as Code with Bicepβœ“

Clicking in the portal is fine to learn; real administration is Infrastructure as Code. Azure’s native IaC language is Bicep (a clean, readable layer over ARM templates) β€” you describe your resources in a file, version it in Git, and deploy it repeatably. Terraform works on Azure too, if you prefer one tool across clouds.

Code (text files)main.tfplan/applyTerraformServersNetwork, DBversion it in Git β†’ rebuild with one command
Infrastructure as Code
Example: Capstone: write a Bicep file that defines a resource group, a VNet, a VM and a storage account, then deploy it with az deployment group create --template-file main.bicep. Your whole environment is now code you can review, repeat and rebuild β€” Azure administration done the professional way.
Where you actually build

Eight labs on real Microsoft Azure

Reading is free and open. The labs are where it becomes real, so they live behind a free account, which keeps your progress and gives you a certificate.

Create a free Kaevor account to launch any lab and earn your certificate. One account, all your courses.

Create free account
πŸ”’

Lab 1 β€” Portal tour + budget

Create a resource group, explore the portal, and set a budget alert.

Portal Β· Cost Mgmt
πŸ”’

Lab 2 β€” Secure your identity

Create users and groups in Entra ID and turn on MFA for an admin account.

Entra ID Β· MFA
πŸ”’

Lab 3 β€” RBAC done right

Assign a scoped role to a group with the Azure CLI, following least privilege.

RBAC Β· az CLI
πŸ”’

Lab 4 β€” Launch a VM safely

Create a Linux VM and lock its NSG down to your own IP for SSH.

Virtual Machines
πŸ”’

Lab 5 β€” Blob storage + SAS

Upload files to Blob Storage and share one with a time-limited SAS token.

Azure Storage
πŸ”’

Lab 6 β€” Deploy to App Service

Publish a web app to App Service and get a managed HTTPS URL.

App Service
πŸ”’

Lab 7 β€” Monitor and alert

Build an Azure Monitor dashboard and wire up one real CPU alert.

Azure Monitor
πŸ”’

Lab 8 β€” Deploy with Bicep

Define a VNet, VM and storage account in Bicep and deploy it as code.

Bicep Β· IaC
Where this takes you

Two levels, one path

Level 1

Beginner (AZ-900)

Cloud concepts, core Azure services, security, identity and pricing β€” the Fundamentals certification foundation.

Level 2

Intermediate (AZ-104)

Administer identity, compute, storage, networking and deployment with the CLI and Bicep β€” the Administrator skill set.